This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to apply policies to all sub-groups?

Been wondering for weeks why my client computers haven't been picking up my policies and it turns out that even if you set the policy at the top of the group any sub-groups underneath do not automatically get the same policies. Fine if you've got a small setup, not so great if you're syncing with a complicated Active Directory structure.

Does anyone know how to do this in Enterprise Console 4.0 or even with an SQL script? Can't find an option anywhere which I think is a bit lame.

:1719


This thread was automatically locked due to age.
Parents
  • Indeed!

    Why CAN'T there be a "replicate down" option?  Or even a "replicate to all policies" within that group?

    If I have let's say 10 or 20 policies in Anti-Vrius Policies and make a change in polices that would true for the other policies, I'd have to change / update all policies accordingly. 

    Real world example:

    If there is a directory I need to exclude in one Anti-Virus Policy, I'd have to add that same exclusion to the rest of my 12 policies manually.

    If I have 60+ sub-OUs under an OU root in AD, if I change a policy at the root, I'd have to go through each and every one of those sub-OUs manually to reflect that.

    Because of the limitations of Sophos Enterprise Console ver. 3 ( and after testing 4, I would include that to the list as well), most of my report creation/AV version management/unmanaged cleanup/virus alerting/errors alerting/update error cleanup administrative actions are handled in OSQL (a manual, time comsuming, non-enterprise solution) on a daily basis. 

    So if OSQL querying is exhausting, complex work why are the customers, like myself, utilizing it and why isn't there a front-end GUI for to implement those OSQL statements instead of us customers having to use or build "undocumented" solutions for existing issues?

    :1792
Reply
  • Indeed!

    Why CAN'T there be a "replicate down" option?  Or even a "replicate to all policies" within that group?

    If I have let's say 10 or 20 policies in Anti-Vrius Policies and make a change in polices that would true for the other policies, I'd have to change / update all policies accordingly. 

    Real world example:

    If there is a directory I need to exclude in one Anti-Virus Policy, I'd have to add that same exclusion to the rest of my 12 policies manually.

    If I have 60+ sub-OUs under an OU root in AD, if I change a policy at the root, I'd have to go through each and every one of those sub-OUs manually to reflect that.

    Because of the limitations of Sophos Enterprise Console ver. 3 ( and after testing 4, I would include that to the list as well), most of my report creation/AV version management/unmanaged cleanup/virus alerting/errors alerting/update error cleanup administrative actions are handled in OSQL (a manual, time comsuming, non-enterprise solution) on a daily basis. 

    So if OSQL querying is exhausting, complex work why are the customers, like myself, utilizing it and why isn't there a front-end GUI for to implement those OSQL statements instead of us customers having to use or build "undocumented" solutions for existing issues?

    :1792
Children
No Data